ClassicPress 2.7.1 Release Notes

We’re happy to announce the release of ClassicPress 2.7.1.

This is a security release.

Security Fixes

  • Users: Ensure a proper email address is used before sending email confirmations.
  • Formatting: Prevent stack overflow in safecss_filter_attr.
  • Multisite: Enforce the active signup policy for existing users.
  • HTTP API: Improve compliance with IPv4 Special-Purpose Address Space.
  • Users: Prevent Usernames from mangling HTML.
  • Comments: Exclude notes from comment feed queries.
  • Canonical: Only redirect for publicly viewable post types.
  • Administration: When wp_is_large_user_count(), ensure that the post author is always added to author dropdown.
  • Media: Prevent loading images into Imagick which might be PostScript.

Contributors

In no particular order the following people have contributed to this ClassicPress release:

ClassicPress props

Matt Robinson, Simone Fioravanti, Tim Kaye.

ClassicPress committers (in random order)

Matt Robinson.

WordPress committers

John Blackbourn, Adam Silverstein, Anthony Burchell.

WordPress props

ehtis, dmsnell, jeremyfelt, westonruter, SergeyBiryukov, aaroncampbell, jorbin, batmoo, johnbillion, lancewillett, tyxla, vortfu, xknown, adamsilverstein, swissspidy, antpb, sippis, gitlost, joemcgill, joedolson, launchinteractive, emirpprime, mwtsn, ceer, maysi, madejackson, 6adminit, costdev, oglekler, wildworks, mukesh27, odkdn1, khokansardar, peterwilsoncc, lucasbustamante, paulkevan, desrosj, jonsurrell.

Download this release

New sites Download
ClassicPress-release-2.7.1.zip
and follow the installation instructions.
Existing WordPress sites Download the migration plugin and follow the migration instructions.
Existing ClassicPress sites Use the built-in update mechanism (more info).

Full changelog

The full changelog is available on GitHub.

1 Like